Sekit CSF · Supply Chain Security · Process
RCF-0329Software supply chain (SBOM)
Software bills of materials are consistently maintained and reviewed for vulnerable or compromised components
Mapping at a glance
RCF-0329Software supply chain (SBOM)Supply Chain Security · Process
RCF-0329 maps to 7 controls across the published frameworks. +2 more in the table below. Open in the full graph →
Maps to ISO/IEC 27001:2022
Curated mapping with the reasoning, not just the codes.
A.5.21Managing information security in the ICT supply chainsupportsKeeping the component inventory current and reviewing it for vulnerable or abandoned dependencies is what makes A.5.21's supply chain visibility hold up as dependencies change.A.8.8Management of technical vulnerabilitiessupportsKeeping the component inventory for each application current and reviewing it for vulnerable dependencies extends A.8.8's exposure tracking into the software supply chain.
Maps to NIST CSF 2.0
Curated mapping with the reasoning, not just the codes.
GV.SC-06Due diligence before engagementID.AM-08Assets managed through lifecyclePR.PS-01Configuration management applied
Maps to Cyber Essentials
Curated mapping with the reasoning, not just the codes.
Evidence that proves this control
What an auditor, or Sekit's evidence engine, asks for.
Application security testing evidence
The proof that code and applications are automatically scanned for flaws (SAST/DAST), including dependencies and APIs.
From the Sekit evidence catalog
This topic through the other lenses
All Supply Chain Security controls
Ask Sekura: “What evidence proves RCF-0329?”
Also via MCP, free with account